cbcvebase.
CVE-2016-5728
published 2016-06-27

CVE-2016-5728: Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to…

PriorityP427medium6.3CVSS 3.0
AVLACHPRLUINSUCHINAH
EPSS
0.40%
33.3th percentile
Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 4.6.1-1 (bookworm)linux 4.6.1-1 (bookworm)
linuxlinux_kernel<= 4.6
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 4.6.1-14.6.1-1
linuxlinux_kernel>= 0 < 3.13.0-95.1423.13.0-95.142
linuxlinux_kernel>= 0 < 4.4.0-36.554.4.0-36.55

CVSS provenance

nvdv3.06.3MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.4MEDIUMAV:L/AC:M/Au:N/C:P/I:N/A:C
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.